CVE-2012-0884: Medium severity openssl vulnerability
The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes it easier for context-dependent attackers to decrypt data via a Million Message Attack (MMA) adaptive chosen ciphertext attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0884?
CVE-2012-0884 has a Medium severity rating due to its potential for causing data decryption vulnerabilities.
How do I fix CVE-2012-0884?
To fix CVE-2012-0884, upgrade your OpenSSL to version 0.9.8u or later, or 1.0.0h or newer.
Who is affected by CVE-2012-0884?
CVE-2012-0884 affects all versions of OpenSSL prior to 0.9.8u and 1.0.0h.
What kind of attack is possible with CVE-2012-0884?
CVE-2012-0884 allows attackers to perform a Million Message Attack (MMA) to decrypt data.
Is CVE-2012-0884 a common vulnerability?
Yes, CVE-2012-0884 is considered a notable vulnerability within cryptographic implementations.